Múltiples vulnerabilidades en TeamViewer

Imported from official source

Advisory

Cybersecurity Classified by Officially

  • TeamViewer Full Client (Windows, Linux y MacOS): versiones anteriores a la 15.82;
  • TeamViewer Full Client v15.64 (Windows 7 y 8): versiones anteriores a la 15.64.8;
  • TeamViewer Full Client v14.7 (Windows, Linux y MacOS): versiones anteriores a la 14.7.48855;
  • TeamViewer Full Client v13.2 (Windows): versiones anteriores a la 13.2.36230;
  • TeamViewer Full Client v13.2 (Linux): versiones anteriores a la 13.2.153995;
  • TeamViewer Full Client v13.2 (MacOS): versiones anteriores a la 13.2.153994;
  • TeamViewer Host v15.64 (Windows 7 & 8): versiones anteriores a la 15.64.8;
  • TeamViewer Host v14.7 (Windows, Linux y MacOS): versiones anteriores a la 14.7.48855;
  • TeamViewer Host v13.2 (Windows): versiones anteriores a la 13.2.36230;
  • TeamViewer Host v13.2 (Linux): versiones anteriores a la 13.2.153995;
  • TeamViewer Host v13.2 (MacOS): versiones anteriores a la 13.2.153994.
  • TeamViewer ha publicado 5 vulnerabilidades de severidad alta, que, en caso de ser explotadas, podrían permitir a un atacante escalar privilegios o ejecutar código arbitrario

    Actualizar TeamViewer Full Client y Host a la versión 15.82 o la última disponible.

  • CVE-2026-19743: validación incorrecta de la ruta en el servicio IPC local permite que un usuario local autenticado con privilegios bajos realice escrituras arbitrarias en archivos con privilegios elevados (NT AUTHORITY/SYSTEM \ root). Un atacante podría enviar comandos IPC manipulados al demonio del servicio local y alterar las rutas de los archivos, lo que provocaría una escalada de privilegios local.
  • This is an extract. The publication continues at the source.

    Read the original at the source: https://www.incibe.es/node/668542

    Officially imported this from INCIBE’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    Provenance

    Organization
    INCIBE — imported from official source
    Official source
    https://www.incibe.es/rss.xml RSS
    Imported
    September 30, 2026 10:30
    Versions
    1 recorded
    Identity
    668542 at https://www.incibe.es

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.